October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
3CX

3CX Supply Chain Attack: How a North Korean-Linked Campaign Reached Crypto Firms

The 2023 3CX compromise began with a trojanized trading app, then moved through the vendor’s build and distribution systems. North Korean ties were assessed with high confidence, but exposure did not mean every customer was compromised.

By TheFinanceBase Team 4 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The March 2023 3CX incident was a cascading supply-chain attack: attackers used a trojanized X_TRADER installer to gain an initial foothold, then compromised 3CX build environments and distributed a malicious version of the 3CX desktop app. Mandiant attributed the activity to UNC4736 and assessed with high confidence that the cluster had a North Korean nexus; later campaign activity targeted cryptocurrency and defense organizations. That does not mean every 3CX customer—or every cryptocurrency firm—was compromised.

How the 3CX supply-chain attack started

The first known link in the chain was not a 3CX installer. Mandiant reported that an employee installed X_TRADER, an end-of-life trading application, on a personal computer. The installer had been downloaded from Trading Technologies’ website and contained VEILEDSIGNAL malware. MITRE ATT&CK dates the campaign’s first observed activity to November 2022; Mandiant identified the X_TRADER installer as the initial intrusion vector in its April 20, 2023 account. Mandiant’s incident analysis and MITRE’s campaign record describe this upstream compromise.

Using access gained through that first compromise, the attackers reached 3CX and compromised Windows and macOS build environments. The resulting malicious software was then distributed through 3CX’s own software channel. MITRE describes this as the first publicly reported case of one supply-chain compromise triggering another; that is MITRE’s characterization of the case, not a timeless claim that no earlier example could exist.

A supply-chain attack is especially difficult for users to spot because the code arrives inside software that appears legitimate. CrowdStrike observed malicious activity—including beaconing and second-stage payload deployment—emanating from the legitimate, signed 3CXDesktopApp binary. Its reporting covered activity on Windows and macOS. CISA’s March 30, 2023 advisory likewise relayed reports of a trojanized app and the possibility of multistage attacks. CrowdStrike’s findings and CISA’s advisory explain what made the downstream app dangerous.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exposure was not the same as confirmed compromise

Being exposed to an affected build means a device received or had access to the trojanized software. It does not, by itself, establish that the malware executed, that the device was successfully compromised, or that an organization suffered a confirmed breach. MITRE says only a subset of 3CX systems were affected, while describing subsequent targeting focused on cryptocurrency and defense sectors.

Term What it means in this incident
Exposure A system had an affected 3CX software build. This alone does not prove malicious execution.
Observed malicious activity Security telemetry showed behavior such as beaconing or deployment of a second-stage payload, as reported by CrowdStrike.
Sector targeting Later campaign activity focused on cryptocurrency and defense organizations, according to MITRE; targeting does not establish that every organization in either sector was compromised.

MITRE’s campaign record, created August 25, 2025 and checked October 4, 2026, says 3CX served more than 600,000 customers and 12 million users. Those figures describe the platform’s audience, not the number of infections. The reviewed reporting does not establish a verified total of cryptocurrency firms successfully compromised or a complete financial-loss figure.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What “North Korean hackers” means here

The attribution is a qualified intelligence assessment, not a public identification of individual hackers. In 3CX’s April 11, 2023 summary of Mandiant’s interim findings, Mandiant attributed the activity to UNC4736 and assessed with high confidence that the cluster had a North Korean nexus. CrowdStrike used the label LABYRINTH CHOLLIMA, while MITRE associates the campaign with AppleJeus. These are different organizations’ tracking labels; they should not be treated as proven interchangeable names. 3CX’s summary of Mandiant’s findings, CrowdStrike’s attribution and MITRE’s campaign entry use those respective labels.

How the incident unfolded

Date What was reported
November 2022 MITRE’s first-seen date for the campaign. Mandiant later described the X_TRADER installer as the initial route into the 3CX environment.
March 29–30, 2023 3CX said it received third-party reports on March 29. CISA published an advisory on March 30; CrowdStrike reported malicious activity from the signed desktop app.
April 1, 2023 3CX said its investigation with Mandiant was under way and gave users incident-period mitigation guidance.
April 11, 2023 3CX published Mandiant’s interim attribution to UNC4736 and high-confidence North Korean nexus assessment. The update discussed TAXHAUL/TxRLoader on Windows, COLDCAT as a downloader, and SIMPLESEA on macOS. It noted that TAXHAUL’s subsequent malware differed from GOPURAM referenced in Kaspersky reporting.
April 20, 2023 Mandiant published its initial intrusion-vector findings. MITRE’s later campaign summary describes subsequent defense- and cryptocurrency-sector targeting and says only a subset of 3CX systems were affected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What 3CX and CISA advised during the incident

These were incident-period directions, not a current warning about every 3CX installation. On April 1, 2023, 3CX told Windows and Mac users to uninstall its Electron Desktop App, continue antivirus scans and endpoint detection and response (EDR) work using current signatures, and use its progressive web app (PWA) client instead. The company’s update said, “Switch to using the PWA Web Client App rather than Desktop App.” CISA urged organizations to consult technical reports and hunt for listed indicators of compromise. 3CX’s incident updates and CISA’s bulletin document that guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not reuse those 2023 directions as a live alert without checking current 3CX advisories and the installed version. For organizations investigating a historical exposure, the useful distinction is whether an affected build was merely present or whether endpoint telemetry shows execution and downstream activity. CrowdStrike also advised removing the software until the vendor said later installers or builds were safe; that, too, was guidance issued in the incident period.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.